This document describes how to migrate from BrightCloud to PAN-DB database if the managed device has Panorama pushed URL Profiles with BrightCloud categories and is configured in multi-vsys mode.
License the Palo Alto Networks device with PAN-DB license and activate the license on the device.
Navigate to Device > Licenses
Click Retrieve license keys from license server or Activate feature using auth code
Download the URL DB initial seed file optimized for a specific region.
Navigate to Device > Licenses
Click Download under the Palo Alto Networks URL filtering
[On the firewall]: Activate PAN-DB (Device > Licenses). This should fail. That is the commit will fail and the local policy will be migrated to PAN-DB, while Panorama pushed policy remains BrightCloud.
[On Panorama]: Switch database on Panorama from BrightCloud to PAN-DB with the following command:
> set system setting url-database paloaltonetworks
[On the firewall]: Remove the Panorama-pushed shared configuration on the firewall. Navigate to Device > Setup > Panorama Settings and click “Disable Panorama Policy and Objects”, click OK to confirm. Note: In the dialogue that appears, do not check the box for “Import Panorama Policy and Objects before disabling”.
[On the firewall]: Enable Panorama to again push the shared configuration to the firewall. Navigate to Device > Setup > Panorama Settings and click “Enable Panorama Policy and Objects”, click OK to confirm.
[On Panorama]: Push the Panorama config one vsys at a time from Panorama
[On the firewall]: Re-activate PAN-DB.
> set system setting url-database paloaltonetworks
In a High Availability (HA) environment, once the device is activated it will come up as "Non-functional" due to DB mismatch with the peer. Follow the additional steps below for the HA environment:
Suspend the Active/Primary device, this will make the secondary device functional.
Follow steps 3 through 9 above.
Note: Both devices are now using PAN-DB, once both devices are functional, failover back to the original Primary/Active device.
Additional Information
Note: BrightCloud URL is no longer sold by Palo Alto. The support will continue till July 31, 2021. Refer to the End of Sale announcements.